Privacy Policy
Effective 2026-07-06
Who we are
Dirhamgrove is operated by DirhamGrove, the data controller for the personal data described here. Contact: privacy@dirhamgrove.com.
What we collect, and why
The statements you import and the transactions, merchants, accounts, and categories they produce. That's the product: showing you where your own money goes. Each person's data lives in their own private space, enforced at the database level, and is never shown to other users. We sign you in with Google and store your name, email, and profile image from that sign-in. We keep a record of when you accepted these terms.
People (contacts from your statements)
Contact details in the statements you import (mobile numbers, IBANs or account numbers, and email addresses) are read on our servers and stored inside your own private account, so People can show you who you send money to and receive it from. They are never sent to any third party or to any AI model, and are shown to you masked. Deleting your account erases them permanently.
Referral program
If you sign up through a friend's referral link, we record the IP address of your sign-up and run an automated bot-detection check when you complete your first statement import. We use these signals only to prevent referral abuse (fake accounts, scripts, and automated sign-ups farming rewards), never for advertising or profiling. The bot-detection check looks at the request itself for signs of automation; it is never sent your statement contents, amounts, or account numbers.
AI processing
Two features send data to Anthropic (Claude), and each sends only what it needs:
- Reading statements you import: the text of the statement is sent so the model can extract transactions. Card numbers and long digit runs are removed before sending, and you review the result before anything is saved. Some statements (often image-based or scanned PDFs) carry no readable text; for those we send an image of the statement pages instead, so the model can read them. Because it is an image, the automatic removal of card numbers cannot be applied to it — the pages are sent as shown. You still review everything before it is saved.
- Categorizing merchants: merchant names only. Never amounts, dates, balances, or account numbers.
Service providers (subprocessors)
We rely on a few service providers to run the app, and send each only what it needs. This list is current as of 2026-07-06. We may change providers as the service evolves; when we do, we'll update this list and tell you about any material change.
- Vercel: hosts the application.
- Neon: the database that stores your data.
- Anthropic (Claude): reads imported statements and categorizes merchants, as above.
- Postmark: sends the emails we send you (receipts, reminders, and optional updates) and, when you turn on email statement import, receives the bank statements you forward to your private import address.
- Google: sign-in only.
- Vercel BotID (powered by Kasada): an automated bot-detection check run on your first statement import to prevent referral abuse. It analyzes the request for signs of automation; we never send it your statement contents, amounts, or account numbers.
- PostHog (EU): usage analytics tied to your account id (which features are used), never amounts, merchant names, account numbers, or dates. Session recording is off.
- logo.dev: fetches merchant logos from a merchant's website name.
- open.er-api.com: provides daily foreign-exchange rates so balances and spending totals can be shown in your chosen home currency. Only an anonymous public rate request is made (no user data, no amounts).
We do not sell your data or use it for advertising.
Email communications
We send two kinds of email. Service emails(import results, payment-due reminders, security and account notices) are part of providing the product, so you'll always receive them. Optional emails (setup tips, your monthly summary, reminders, and product updates) are sent only if you've left them on. You can turn any optional category off any time in Settings, or use the unsubscribe link in any such email. To understand whether our emails are useful, we record when one is opened and when a link in it is clicked. Email is sent by Postmark on our behalf, and we never include your transaction amounts in an email.
Where your data is stored
Dirhamgrove runs on infrastructure outside the UAE: the app and database are hosted in the United States and Europe (Vercel, Neon), and AI processing by Anthropic takes place in the United States. By accepting our terms you consent to your data being processed in these locations.
Retention
We keep your data while your account exists. Delete your account and it's gone, immediately and irreversibly.
Children
Dirhamgrove is not directed at minors and we don't knowingly collect their data. Accounts found to belong to minors will be deleted.
Your rights
From Privacy & datain the app you can export everything you've added as JSON, or permanently delete your account and all of your data. Both work even if you decline an updated version of our terms. Deletion is immediate and can't be undone.
Security
Your data is isolated per account at the database level (row-level security), access is limited to what each feature needs, and we keep a security log of sign-ins and sensitive actions.
Saved statement passwords
If you choose to have us remember a statement password for one of your products, we store it encrypted at rest (AES-256-GCM) and use it only to open that product's statements. You can delete it at any time from the product's settings, and it is removed if you delete the product or your account. The saved password is never displayed, returned to the browser, or included in your data export (the export notes only whether a password has been saved).
Email statements you forward
If you turn on email statement import, you get a private address to forward bank statements to (or to set a one-time auto-forward rule). We accept mail only from senders you have approved, verified by DKIM, and we read the PDF to import its transactions exactly as a manual upload. We do not keep the email itself.
If a statement cannot be imported automatically, because we cannot match it to one of your accounts or it is password-protected, we keep that one statement file encrypted for up to 14 days so you can finish importing it from Activity, then we delete it. You can delete it sooner from Activity, and it is removed if you delete your account.
Changes to this policy
When we make a substantive change, we'll publish a new version with a new effective date and ask you to review and accept it before you continue using the app.
Contact
Questions, or want your data removed by hand? Email privacy@dirhamgrove.com.
See also the Terms of Service · Back to sign in